arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2502.07011cs.LGcs.CRcs.DC

DROP:基于知识蒸馏的联邦学习投毒稀释

DROP: Poison Dilution via Knowledge Distillation for Federated Learning

  • Northeastern University(东北大学)
  • University of California, San Diego(加州大学圣地亚哥分校)

机构由 AI 辅助整理,请以论文原文为准。

Georgios Syros, Anshuman Suri, Farinaz Koushanfar, Cristina Nita-Rotaru, Alina Oprea

更新

AI总结:

针对联邦学习中的定向后门攻击,提出DROP防御机制,结合聚类、活动追踪与知识蒸馏提取良性行为,在多种配置及非独立同分布数据下展现出卓越鲁棒性。

AI中文摘要:

联邦学习容易受到对抗性操纵,恶意客户端可以注入投毒更新以影响全局模型的行为。尽管现有的防御机制取得了显著进展,但它们无法防御旨在不同学习和攻击配置下诱发定向后门的对手。为了解决这一局限性,我们提出了DROP(基于蒸馏的投毒削减,Distillation-based Reduction Of Poisoning),这是一种新颖的防御机制。它将聚类与活动追踪技术相结合,并通过知识蒸馏从客户端提取良性行为,以应对在联邦内操纵低数据投毒率和多样化恶意客户端比例的隐蔽对手。通过大量实验,与现有防御相比,我们的方法在广泛的学习配置下展现出卓越的鲁棒性。最后,我们在非独立同分布(non-IID)客户端数据分布这一具有挑战性的设置下评估了现有防御和我们的方法,并强调了在该设置下设计具有弹性的FL防御所面临的挑战。

英文摘要:

Federated Learning is vulnerable to adversarial manipulation, where malicious clients can inject poisoned updates to influence the global model's behavior. While existing defense mechanisms have made notable progress, they fail to protect against adversaries that aim to induce targeted backdoors under different learning and attack configurations. To address this limitation, we introduce DROP (Distillation-based Reduction Of Poisoning), a novel defense mechanism that combines clustering and activity-tracking techniques with extraction of benign behavior from clients via knowledge distillation to tackle stealthy adversaries that manipulate low data poisoning rates and diverse malicious client ratios within the federation. Through extensive experimentation, our approach demonstrates superior robustness compared to existing defenses across a wide range of learning configurations. Finally, we evaluate existing defenses and our method under the challenging setting of non-IID client data distribution and highlight the challenges of designing a resilient FL defense in this setting.

↑